MATCHBOIL malware: UAC-0099 expands Ukraine targeting
ESET has published research tracing nearly two years of development of MATCHBOIL, a Windows downloader used by the Russia-aligned group UAC-0099. The group uses it to drop a spying backdoor on machines in Ukraine.
According to ESET telemetry, every victim was located in Ukraine. Transportation companies were hit in July and August 2025, a manufacturer in December 2025, and an energy company in June 2026. Researchers say the access the malware creates could also be useful to other threat groups.
A downloader for a spying backdoor
MATCHBOIL does not do the spying itself. Its job is to fetch and install a second program.
"We have seen in ESET telemetry that MATCHBOIL downloads a payload known as MATCHWOK, a C# backdoor with capabilities for espionage on the victim's machine. For example, it can take screenshots of the victim desktop or execute PowerShell commands on the victim's computer," ESET researcher Fernando Tavella told Help Net Security.
The attack begins with a spear phishing email containing a link. Clicking it downloads an archive with a VBScript file, which then downloads and launches MATCHBOIL.
Once running, MATCHBOIL fingerprints the system using the CPU ID and the BIOS serial number. It then sends three HTTPS requests to the attackers' server. The second response is an HTML page with the payload hidden inside as hex-encoded text. MATCHBOIL extracts it, saves it to a folder under %LOCALAPPDATA% and makes sure it restarts, either through a scheduled task or a Windows registry key. If the target folder is already there, the downloader simply exits.
Names to hunt for
The location of the payload has changed several times. In 2024 it was stored in a folder named DeviceMonitor. By late 2025 the file was called MeowMeowProgramm.exe and sat in a folder named MeowCheck. In the April 2026 version it appeared as SMTPClientApplication.exe in a folder called SMTPClient, with a scheduled task named Checker placed under a directory named MailClient.
These names are the indicators defenders should look for when checking a potentially infected machine.
More resilient, harder to analyze
Early builds of MATCHBOIL ran only once and depended on the persistence mechanism for everything else. By late 2025 the downloader ran on a two-minute timer, so a failed first connection to the server no longer ended the infection.
The developers also dropped their own string scrambling in favor of a commercial obfuscator, Eziriz .NET Reactor. The tool can virtualize code and complicate its control flow, which makes reverse engineering harder.
Sandbox detection arrived around the same time. MATCHBOIL reads Windows event logs for system uptime, searching in both English and Russian. It only assumes it is on a real machine if it finds at least three events showing 7,200 seconds (two hours) or more of uptime. The April 2026 version added another check: the operating system must have been installed at least ten days before the malware runs.
The decoy, by contrast, is rough. Late 2025 builds display a daily planner with a cat photo to anyone who opens the file manually. The window is titled "Dairy," and both text fields carry the label "Today."
New sectors in the crosshairs
UAC-0099 has previously been linked to attacks on government bodies, financial institutions and media in Ukraine. The transport, manufacturing and energy victims mark a change.
Asked whether this points to a broader target list, Tavella referred to the group's past:
"UAC-0099 has been targeting different entities in Ukraine. We believe that the group has different interests and their expansion in the victimology could mean that they are seeking to maximise their impact in UA. Let's remember that this group has been an initial access broker of Sandworm, another Russia-aligned APT group, so it is possible they are seeking victims that can be of interest for other APT groups that UAC-0099 can assist."
An initial access broker breaks into networks and passes that foothold on to another actor. ESET attributes UAC-0099 to Russian interests with medium confidence, based on who it targets.
MATCHBOIL was first documented in August 2025 by CERT-UA, Ukraine's government computer emergency response team. Compilation timestamps in those samples date to mid-2024, which suggests the tool was in use for about a year before it was publicly described.
On the infrastructure side, UAC-0099 rents virtual servers from providers such as BitLaunch and places Cloudflare in front of them. ESET also found that the group does not reuse its Let's Encrypt certificates across domains.
The Bigger Picture
MATCHBOIL is not technically groundbreaking, and the clumsy "Dairy" decoy shows its authors care more about function than polish. What stands out is the steady, practical improvement: retry timers, commercial obfuscation, sandbox checks and regularly rotated file names. This suggests an operator focused on staying hidden long enough for the foothold to matter.
The shift toward transport, manufacturing and energy is the more important signal. If UAC-0099 is indeed acting as an access broker, a compromised energy company could become a starting point for a more destructive actor such as Sandworm. That fits a wider pattern of attackers probing critical infrastructure operators, and it follows other recent campaigns aimed at Ukrainian users, such as the Lunex Stealer operation.
The year-long gap between first use and public disclosure is also a reminder that tools like this can run quietly for a long time. It is worth watching whether MATCHBOIL appears outside Ukraine, and whether follow-on intrusions are tied to victims it has already reached.
